Create
Your browser encrypts the secret before upload. The decryption key stays in the complete link—not in VanishKey storage.

Your browser encrypts the secret before upload. The decryption key stays in the complete link—not in VanishKey storage.
Send the link however you prefer. Its reveal capability stays after the #, beyond ordinary link previews.
The recipient confirms reveal once. That retrieves and permanently deletes the encrypted copy. Unopened links expire after one hour.
The concrete controls behind the disappearing act—not a hand-wavy "military-grade" label.
AES-256-GCM Local authenticated encryption256 + 256 Split reveal capability#; ordinary HTTP requests and link previews do not send that fragment.TTL 3600 Ephemeral in-memory ciphertextATOMIC Single-use retrievalSecurity boundary: anyone holding the complete URL can reveal the secret. Direct email intentionally passes that URL through VanishKey and Mailgun. The AES key is never stored in the in-memory secret record.
Give people, AI agents, and automated workflows the same private way to share credentials without placing them in chat or logs. Our lightweight client encrypts locally and returns a single-use link.
Local encryption • no readable secret storage • one-time access